Executive brief
Milestone Systems has addressed a critical security flaw in XProtect, a widely used video management software for security surveillance. The vulnerability allows an administrative user with edit permissions to execute unauthorized commands on the central management server. This could lead to a complete takeover of the surveillance infrastructure, potentially allowing attackers to disable security monitoring or access sensitive video data.
Technical details
A vulnerability classified as OS Command Injection (CWE-78) exists in the Milestone XProtect Management Server API. The flaw allows an authenticated attacker with high privileges (specifically 'edit' permissions) to execute arbitrary code in the security context of the Management Server Service. While the attack requires high privileges (PR:H), it results in a scope change (S:C) because the attacker can move from the application layer to the underlying operating system. Milestone has released a new version of XProtect and cumulative patch updates to remediate this issue.
Affected products
- Milestone Systems XProtect Management Server <= 25.3
Timeline
- 2026-07-14: disclosed
- 2026-07-14: patched